Apppresser develops a mobile app framework product that, despite a narrow footprint, sits in a prominent position for WordPress-based mobile application development and deployment. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through application-layer weakness classes including cross-site request forgery, weak password-recovery mechanisms, and improper handling of missing or exceptional conditions that reflect the authentication and input-validation demands of a web-app-to-mobile bridge. Defenders deploying this framework should prioritize patch cycles and review authentication and session-management implementations; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apppresser over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4214CRITICAL The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code | Nov 18, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-11024CRITICAL The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to th | Nov 26, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-9305CRITICAL The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to th | Oct 16, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-4611HIGH The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up to | May 29, 2024 | 8.1 | 24 | NO | NO |
CVE-2024-31374HIGH Cross-Site Request Forgery (CSRF) vulnerability in Scott Bolinger AppPresser apppresser allows Cross Site Request Forgery.This issue affects AppPresser: from n/a through <= 4.3.0. | Apr 15, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-31268HIGH Cross-Site Request Forgery (CSRF) vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0. | Apr 12, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-1561MEDIUM The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 4.4.10 due t | Mar 13, 2025 | 6.1 | 20 | NO | NO |
CVE-2024-32776MEDIUM Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0. | May 14, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apppresser.
Media articles that mention a CVE ID that affects a product developed by Apppresser — matched by CVE ID, not by vendor name.